Dropped Files | ZeroBOX
Name 5c7ffa42a20047ad_unins000.dat
Submit file
Filepath C:\Program Files (x86)\PC Cleaner\unins000.dat
Size 29.0KB
Processes 2156 (PC_Cleaner.tmp)
Type data
MD5 57005b417cbb89ebe971f36d426fd650
SHA1 7b9dd15817b0e63f601fa4790f2ec0b0e16ddfd5
SHA256 5c7ffa42a20047ada221a37e02e44f1802a849693b15ebd4ff553c7dcefb38db
CRC32 B0AE9A79
ssdeep 384:fbeEnozelF97uVuOannr9EYF/oDy08plYbPIzOgLFHD:fbChbgn
Yara
  • Antivirus - Contains references to security software
VirusTotal Search for analysis
Name 502f9fba9bba2ca5_cookies.txt
Submit file
Filepath c:\program files (x86)\pc cleaner\cookies.txt
Size 104.0B
Processes 2156 (PC_Cleaner.tmp)
Type ASCII text, with CRLF line terminators
MD5 bf6c156441320d21440afc65a6bcf77d
SHA1 b04bb3fa963147218ef2c79e96a5a3e1d899e94d
SHA256 502f9fba9bba2ca5f57a3a0ea7efcee4731c98dcd2ea0fcec21059b11ddbf352
CRC32 9B7B9D33
ssdeep 3:dIEWKKBnCpvTOvDxRVlDEKTkgn:tWKKBnCvTObvVBEKTb
Yara None matched
VirusTotal Search for analysis
Name f7a31bccda8782cc_finnish.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\finnish.ini
Size 78.2KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 90a6c8d33f0d27c0be8dbad87a4e808b
SHA1 9eaf58f1fba6acbfb4f154e44ba4a42c35c34b3f
SHA256 f7a31bccda8782ccb0079cf2aa94876a70a8cb4143d6299e2e11f61533f891f2
CRC32 ED67A384
ssdeep 1536:WVCHxazxzK1UenhfossUV9jukUrtMOLx6sxBsN+zLUvRiZ+viRxjwum2zwIhChj/:9xazxe1UenhfossuukUrCOLx6s/sszyv
Yara None matched
VirusTotal Search for analysis
Name db70fac74d73f707_pc cleaner.lnk
Submit file
Filepath C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Cleaner\PC Cleaner.lnk
Size 1.0KB
Processes 2156 (PC_Cleaner.tmp)
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Wed Dec 13 14:00:31 2023, mtime=Wed Dec 13 14:00:31 2023, atime=Fri Mar 5 02:06:12 2021, length=9000864, window=hide
MD5 8151a07040a45d395363208a141b9240
SHA1 270c028e9d3b61aea6ed2a47cb00d6e56dfffb75
SHA256 db70fac74d73f70709258859aa76ac7a1611e2872da538c326286b80b7b0e41c
CRC32 22CCC52C
ssdeep 24:8mdVdOEkYSmScBxA6k/ldnmJWdnmlUPPyN:8mdVdOvMQ6ednwWdnTnyN
Yara
  • lnk_file_format - Microsoft Windows Shortcut File Format
  • Antivirus - Contains references to security software
  • Lnk_Format_Zero - LNK Format
VirusTotal Search for analysis
Name 5f6a3ae97f57128f_brazilian.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\brazilian.ini
Size 80.4KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 c008b7f22b91dbf9fe2f2314d2a643d0
SHA1 328f6da52060aaec8f6a1a32e4714ffe8ad3376e
SHA256 5f6a3ae97f57128fc05e680eb6d5c10fdad1811ad692bc6d5afd2719b2b483f9
CRC32 3AD1FD7C
ssdeep 1536:LhY05yc/yQIUrWgTMxe2lb7JhIoLbyM34cYEXuVgtk7kAF:FYcdbKe2lb7JhIoL2y4csyckAF
Yara None matched
VirusTotal Search for analysis
Name d3c1fe40b3b955e0_uninstall pc cleaner.lnk
Submit file
Filepath C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Cleaner\Uninstall PC Cleaner.lnk
Size 1.0KB
Processes 2156 (PC_Cleaner.tmp)
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Wed Dec 13 14:00:31 2023, mtime=Wed Dec 13 14:00:31 2023, atime=Wed Dec 13 13:55:33 2023, length=3021728, window=hide
MD5 107aa6322f6ff9befc5974f6d8475d55
SHA1 85215bac4fc0e1dbf1db94562f1a6e3c550feeb0
SHA256 d3c1fe40b3b955e00aa9a127164987acd94f3469c9a9c6f54f352243822423de
CRC32 6D5EF0AA
ssdeep 24:8mBkrdOEkYSm7oUAxk/WdnmFEdnmlUPPyB:8mBedOvmojx/dnEEdnTnyB
Yara
  • lnk_file_format - Microsoft Windows Shortcut File Format
  • Lnk_Format_Zero - LNK Format
VirusTotal Search for analysis
Name 6a7502049c4f51e4_swedish.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\swedish.ini
Size 75.1KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 37830b2018ff13d954cd3dbd493b10cd
SHA1 40f68b1ea78f2232447f817b8df7141a060f2bad
SHA256 6a7502049c4f51e4bab831284946ebd94c3d8784303e26c986c0a1ac8094b94c
CRC32 C9255CEE
ssdeep 1536:kGQ4zWL9Jzy6P2bmVBe2qT5wwQ1g00HyV1Mv:y19JmQ2bmVY6uHyMv
Yara None matched
VirusTotal Search for analysis
Name c0750a98e70330ce_slist.txt
Submit file
Filepath c:\program files (x86)\pc cleaner\slist.txt
Size 77.3KB
Processes 2156 (PC_Cleaner.tmp)
Type Non-ISO extended-ASCII text, with CRLF line terminators
MD5 76f1c55b6bae1d7ef4ae1c1f0e0bd828
SHA1 f05a7d76139269bb9ada900cc97c0c67d422ae53
SHA256 c0750a98e70330ce53113529598cae8b0974b66be05148071fbab33570b087b5
CRC32 6239C3A5
ssdeep 1536:1VtVSx3JVA033wYcwjSXAiy5WGmJQ2r3O:/SLSqRDj6AiyINe
Yara None matched
VirusTotal Search for analysis
Name 26a3195f988a127a_french.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\french.ini
Size 86.3KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 1e0336ce1bfd65fe3a4838d5c9449858
SHA1 471c441a3b388a86ad225cf0d9155f4c599e903a
SHA256 26a3195f988a127a2e8211fcadc7a1c6ef157ed4491d53b8472df3881f03a455
CRC32 342A80F5
ssdeep 1536:FewQ2fWp8bfrYLEKZkfjUxwYdaM0QcAHhOhyB2vLSNffM3T4jjeggHsWNms:FewfwyrYpxuhQcAHRa4fegHWcs
Yara None matched
VirusTotal Search for analysis
Name cc9a1bcb73ac29d2_italian.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\italian.ini
Size 79.4KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 183a580bff5b1fb90f46c0c4a875f5f6
SHA1 9025a983d648287f3c1a707dc47fd2770904e547
SHA256 cc9a1bcb73ac29d281e62716b8032294367748cfa694bb3a734e751723efe2d5
CRC32 8A68A875
ssdeep 1536:9QjeOWZsHAlBvAfqvoOEbDLTkopJ0CvpY/Yulvx8jpZtw5zS+AITnJ:9QjeOWLpAfqvBEbDLTkojnRY1rYpZtEZ
Yara None matched
VirusTotal Search for analysis
Name 24601e1d57ea2f9e_german.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\german.ini
Size 83.1KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 9d80fce22b351bdce88f8d670f31b2d6
SHA1 88d55321905140ef85a75a2feec0bca98bbd769a
SHA256 24601e1d57ea2f9ee75a41019ec74ea6ee8b5419518c55a33a9152d650a31ca6
CRC32 27FC9E13
ssdeep 1536:m0p8Ov7IiUGosUfea9GnqHmVTLNsPdjPSOz1KH7oVkZQpxacN0bUlXZI2RFaMprA:ue7IBGKGnXNsPlsHul4Ue
Yara None matched
VirusTotal Search for analysis
Name 75fd81f57ad77f15_services2.txt
Submit file
Filepath c:\program files (x86)\pc cleaner\services2.txt
Size 14.2KB
Processes 2156 (PC_Cleaner.tmp)
Type ASCII text, with CRLF line terminators
MD5 340b31f1de820e89fdab9cdb659511e9
SHA1 0c2c8a01e052330e3c24fad548abe38cd4932b19
SHA256 75fd81f57ad77f15ec5444d736a6b16b48d163c8bf1051c6511662ee50a8fa67
CRC32 CEE654A7
ssdeep 96:4u4y64zqfQY0/XDlBZkJVPhbC6UJw3OaeOd9CYp1NKMU2SmwqC55BwSLhLLwtwYR:NY4pAefk12T/5YzpftOC+WNB5/fXGaZ
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
VirusTotal Search for analysis
Name 155fd71b9bb08ab4_japanese.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\japanese.ini
Size 98.6KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 36890264eb17b79182973e9558af89af
SHA1 1e4752d3cd7b36d854032c065496dcbfa32cfe40
SHA256 155fd71b9bb08ab48eceec86c737a5e019aca0a2f6e18651ac64c9df4fcf7a66
CRC32 6CC8D707
ssdeep 1536:EfZJLdH2hSjV2ZtssQmt2PvnJutSrdeot6uz2I9Y1gsmkCr86DBe:EfZJLdH2hS2ssQmtqauX6uz2I9xkCr8f
Yara None matched
VirusTotal Search for analysis
Name b59785f62c26b60c_slist.db
Submit file
Filepath c:\program files (x86)\pc cleaner\slist.db
Size 1.0MB
Processes 2156 (PC_Cleaner.tmp)
Type SQLite 3.x database, last written using SQLite version 3011000
MD5 ddbbfda211ed1460d616a48fe1ef9676
SHA1 5306fba67448ab0c1c3e55808d13b1f900e82493
SHA256 b59785f62c26b60ce5d6e30e88946bffc3d7eb8c0f572359d36985ca8ee4bc48
CRC32 1865397C
ssdeep 24576:WY8IyylDzjpmRFQn0g5cqhJWT2mZws7noPrbLT:JrlhyLu
Yara
  • Malicious_Library_Zero - Malicious_Library
  • Sality_IN - Sality
  • Antivirus - Contains references to security software
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • ftp_command - ftp command
  • Generic_Malware_Zero - Generic Malware
  • DllRegisterServer_Zero - execute regsvr32.exe
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name aac7686c91905beb_homepage.url
Submit file
Filepath c:\program files (x86)\pc cleaner\homepage.url
Size 112.0B
Processes 2156 (PC_Cleaner.tmp)
Type MS Windows 95 Internet shortcut text (URL=<https://webtools.avanquest.com/redirect.cfm?eredirectId=pchelpsoft/pc-cleaner-home.htm>), ASCII text, with CRLF line terminators
MD5 be9fa384b022bc6a75b1a08d9788fbd6
SHA1 37d3169f8a670aa71ce10e66df23e6316c74500d
SHA256 aac7686c91905beb01b424f3cf446e92880e6907eea452925b7c04525be59ab3
CRC32 216F5B7F
ssdeep 3:HRAbABGQYm2f5xk6EgQztGTGY3ss057ylPF:HRYFVm4ZEgJTGyd
Yara
  • url_file_format - Microsoft Windows Internet Shortcut File Format
VirusTotal Search for analysis
Name bebde1daa07b9f2c_sitentf.txt
Submit file
Filepath c:\program files (x86)\pc cleaner\sitentf.txt
Size 4.2KB
Processes 2156 (PC_Cleaner.tmp)
Type ASCII text, with CRLF line terminators
MD5 b8dd8bdac1510ef2fb80b5f6cb43b71d
SHA1 e5efffaa40f1bbc65a91fe09b29ebf655df88315
SHA256 bebde1daa07b9f2caee5006af0cfd6d43df7c69f7797981ac4f088b26944a190
CRC32 15F9C650
ssdeep 96:kxXH+TBvERKDzCxLg+lQm+zHj6DnojA4EBhqmhEWl7GMCdM9:kReFE0DzgMn3zD6DnoSZhEWl7GMGe
Yara None matched
VirusTotal Search for analysis
Name e1ef0762a289d215_PC_Cleaner.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-U68DC.tmp\PC_Cleaner.tmp
Size 2.9MB
Processes 2080 (PC_Cleaner.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 c00b8f7688b66e273c7ada486ffbf29f
SHA1 09dd13a361f8fd15a0a5e4db9b0e01c143f0149d
SHA256 e1ef0762a289d2152741c1f62d701f0a7ba11f82f03bbd9e2d947e27308ffcfc
CRC32 DB8FF947
ssdeep 49152:2LJwSihjOb6GLb4SKEs3DyOMC2DlUt0+yO3A32ASNTvu9:ywSi0b67zeCzt0+yO3kSg
Yara
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 11277ae487362fc0_schedtasks.txt
Submit file
Filepath c:\program files (x86)\pc cleaner\schedtasks.txt
Size 6.4KB
Processes 2156 (PC_Cleaner.tmp)
Type ASCII text, with CRLF line terminators
MD5 636908c786dfe5783754d4b489ab7d17
SHA1 9024e7f3ac8d9a990398e8362d1fb53b39ad75f5
SHA256 11277ae487362fc06a48174d679f59678d50da4b264a776f491f1e389570bc8c
CRC32 FF89DDC0
ssdeep 192:iPHHfnYHvvC2bKUdsjMXYAUSmexdNYzjsMc:iPf2vC23UfexdN/
Yara None matched
VirusTotal Search for analysis
Name 95d33968b7451747_services1.txt
Submit file
Filepath c:\program files (x86)\pc cleaner\services1.txt
Size 3.2KB
Processes 2156 (PC_Cleaner.tmp)
Type ASCII text, with CRLF line terminators
MD5 21bc09207f237dd262112401584e3b8f
SHA1 7aa202d5d392e9c3b04c0113381d165a3b12ff61
SHA256 95d33968b745174744e07207e8003b8a615e1bc5e10676a2f4e81f3e5abf4980
CRC32 7B357A9A
ssdeep 96:zXOk/Ty2JCNSwdT4BaA+Gm8Rfcyz0U+fs1qV:zXOkBJCIwdTA+GQK0U+fs1+
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
VirusTotal Search for analysis
Name 135d81feef8bc93e_animation.gif
Submit file
Filepath c:\program files (x86)\pc cleaner\animation.gif
Size 3.9KB
Processes 2156 (PC_Cleaner.tmp)
Type GIF image data, version 89a, 48 x 48
MD5 915f2ce934fd4789216b91bf9c2609fd
SHA1 cb942f9e699d07f85a008e8131bb8a92a3974f87
SHA256 135d81feef8bc93e48f3d929d9249abe56e8b0a566f51964c8cad28602219250
CRC32 025FA10E
ssdeep 96:I796+qTY+rVj7rP0G3Vd3AbHAEv5+XBBWFVUUfkkVcya3Bu:I79bqk6nL987GBERc2h0u
Yara None matched
VirusTotal Search for analysis
Name 5c3a688b292ce9cd_unins000.msg
Submit file
Filepath C:\Program Files (x86)\PC Cleaner\unins000.msg
Size 23.5KB
Processes 2156 (PC_Cleaner.tmp)
Type data
MD5 d3690e7e35cea79b66d17a069c3b947b
SHA1 cee595de103e3e46cee46d7e303a1b7876e44874
SHA256 5c3a688b292ce9cd98290bc1f4c525ccf42e3537ca704555c8bf058fdef10d27
CRC32 850B7268
ssdeep 192:b1EjNSCkf3SCqsTr6CCPanAG1tznL7VF+Iqfc51U5YQDztXfbKJG/Bfvg:b1EK6CHr6fSX+7Q1U5YQDztB/B3g
Yara None matched
VirusTotal Search for analysis
Name d50cc3fd6c2566e7_turkish.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\turkish.ini
Size 82.4KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 cda8f79f5007df3821e7b57bd02b3c5a
SHA1 631277dea33438f20cbf971dfcf50c68e52ed571
SHA256 d50cc3fd6c2566e7cd568a03c8257c6e0703424f54e73c23e1df26fab8bd7ac4
CRC32 7A7582D9
ssdeep 1536:mevPrVQcxOW8Y0atSixXsdxLvHXSXDBNAV5xPgAlh61jrX3Q54SnEDn:Nh9SYDtSGXsdxLvHKcV5xYAlh6ZrS4S6
Yara None matched
VirusTotal Search for analysis
Name 1bfb784bcb7a5fe4_polish.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\polish.ini
Size 83.0KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 37ed6c3502649cea4db8abfbb37e21bd
SHA1 7d09f11108a7a81d76e00316aadcf24ed9582fd1
SHA256 1bfb784bcb7a5fe471d0aaf6e4e4a3336ebede611dd5a75c5d7a28aecbd1cbc1
CRC32 A2160AF7
ssdeep 1536:SMLpGEJ6FjkaQRY3dqBUKsmb/szucRC0RYkw6sdKZ9SKZ:Su6FjkTY3dqmKsmb/sacRMkZsIfDZ
Yara None matched
VirusTotal Search for analysis
Name d0bc9a81e0ab3f82_spanish.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\spanish.ini
Size 83.0KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 b01e5be9b31d08eed668e9eb46e08d20
SHA1 dd9422f8fcd7ed7f614a9b68a8aa32a513a3c627
SHA256 d0bc9a81e0ab3f829bfe8234160642e5711a3272c046469b41574260840110fa
CRC32 4DE35766
ssdeep 1536:76GDjMbwPjDo54t6oK9eBDNQs7cSY++I0u+l8K:WcjSKBDNQmcg+lz
Yara None matched
VirusTotal Search for analysis
Name 0ca90be9c0172822_pccleaner.exe
Submit file
Filepath c:\program files (x86)\pc cleaner\pccleaner.exe
Size 8.6MB
Processes 2156 (PC_Cleaner.tmp)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 48d9169285d12bbdd870aadafbb2d5b9
SHA1 9fee8648325d4f772ddc92f12d8e0c6603b05b40
SHA256 0ca90be9c0172822fe6fc3d823eb52950fc9c5a4d05f236a288aa20deec891f8
CRC32 40C55F60
ssdeep 98304:wLh6bpX5g5AxNKmzrxdFMHtO3Ouyn64GiZMpU:5HJdEwWFQpU
Yara
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • Antivirus - Contains references to security software
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name f08e42743312435a_chinese_tr.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\chinese_tr.ini
Size 64.4KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 d6814cf25731615c29ad8b82881f0de5
SHA1 d380a0b57b50871795c042079d209c089dcd2e9b
SHA256 f08e42743312435a5880d3ca5231f47b2c073ffe9fd93679d1e8472bba35fb88
CRC32 18882B96
ssdeep 1536:7RhXWx36UHWxT8d6DTZF6wmMVQ7aH6F8rhPyGtvTnOdW:jaJ2iEnZF6wm2oVK0W
Yara None matched
VirusTotal Search for analysis
Name 317b849e6ca97956_pccnotifications.exe
Submit file
Filepath c:\program files (x86)\pc cleaner\pccnotifications.exe
Size 4.3MB
Processes 2156 (PC_Cleaner.tmp)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 6b5db480c96f652f1f5fd6a1bf9d8181
SHA1 44b785dc215fd6a88b88bb08aa4df530d017091e
SHA256 317b849e6ca97956ec27b4a3c9d87ec80b885509a3bf4ab1aaa62f2874f4ace1
CRC32 29C6530B
ssdeep 49152:CQjcpWAThcJASG3a7utbsqbj7qBds//Cp1Pgcgf2KCqXsYuTuK9h9:CQApWAkutsq7qBdsXCp1Ycgf2KCqXzu
Yara
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • Antivirus - Contains references to security software
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 789ad542e7592b45_norwegian.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\norwegian.ini
Size 73.5KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 c0ecb771b96c676e29cbdf985554f6b9
SHA1 65d01d94f289711f7baf495d51970d0264906dd7
SHA256 789ad542e7592b452e935a8eb888eef5fa4444ae7370f8a4988784fb340951d3
CRC32 67065B24
ssdeep 1536:Sze8hmoBdKV8xcM2HSMwzjiYgG5eFC1Sh1hCxE2BEhP:zsmobKSxcM26L5CLh1hCxEoq
Yara None matched
VirusTotal Search for analysis
Name 8e827bdb70695223_pc cleaner on the web.lnk
Submit file
Filepath C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Cleaner\PC Cleaner on the Web.lnk
Size 1.0KB
Processes 2156 (PC_Cleaner.tmp)
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Wed Dec 13 14:00:32 2023, mtime=Wed Dec 13 14:00:32 2023, atime=Mon Feb 15 00:42:18 2021, length=112, window=hide
MD5 68a687e51eca0420311ee490dc797005
SHA1 9c92a32cf5fc0d50a0ffaa71af261c2947241549
SHA256 8e827bdb7069522353ca9d33503cfda23e8dd5f59e7d9d058df0a73f2b3ca668
CRC32 3CF50499
ssdeep 12:8mE1h20AycGdp8DCDc0P2HolWNmp/ZRSXAjAxk/UbdpYKmpkbdpYKmp3BNU94t2K:8msdOEkYSm0UAxk/AdnmOdnmlUPPyB
Yara
  • lnk_file_format - Microsoft Windows Shortcut File Format
  • Lnk_Format_Zero - LNK Format
VirusTotal Search for analysis
Name 07922e7b3c18165a_korean.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\korean.ini
Size 82.9KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 e0473641913a1c68318658aab94cea48
SHA1 3a71aa6e83b8436accacfa4c1ab536980cbd2c51
SHA256 07922e7b3c18165a1e7a1b097fdd2a31a1af49f34a9204994c708a67ef25b7e2
CRC32 176FE173
ssdeep 1536:b6OPYQoM7AZ5jOcyH0ZRIWXBw1Lpqm+CBH0OgfVdIcmV1QZonVQVJVhqdoKB+bM3:b6OPYQF7AZtVyH0ZRIuBw1LpqmV0Ogf6
Yara None matched
VirusTotal Search for analysis
Name 18d5885bebb02d1e_portuguese.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\portuguese.ini
Size 82.1KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 b5ace6bf5deda1d4b1954f5934abbfad
SHA1 754dca8cecdd406ca7d091db625fde2fcea7cdf0
SHA256 18d5885bebb02d1e6598b3671e83da20ce08e5ad8b1a9af4954411395138b0b9
CRC32 3708DC17
ssdeep 1536:Nlwgib7gplGcUJrRDR6yW+1GT6yMmQk/RZkUnZGr0iB:N62KcorZR6yW+1GT1RZkUe0iB
Yara None matched
VirusTotal Search for analysis
Name eca58a1e8e8f25ae_english.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\english.ini
Size 68.6KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 d785e4f5ac56806ae58dfaacc1cdfa8b
SHA1 6a22e46e60344c2aabd65bf49d51b486e661f553
SHA256 eca58a1e8e8f25aef03133eed17ecff2844274be4ccd8c5d94b9d99d70d3a9d0
CRC32 C1EE73D6
ssdeep 1536:gItq+ZO9ZAdHFQQaVDcK6W8EeOeO1NC5Pr44z4FaQyBW7M9G3/eY:hpYeOjf1NC5z+zyBFQ
Yara None matched
VirusTotal Search for analysis
Name 79d3dcb723f3ab23_chinese_sm.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\chinese_sm.ini
Size 65.9KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 00ffc66068531c86e7d7ff7b005c55b5
SHA1 bbc1b8a278532042e58c29845e88dd7d2272840e
SHA256 79d3dcb723f3ab23d96699b7a0b7469198593b07b7f00ec4a6a97e035f521612
CRC32 65B64745
ssdeep 1536:HBWB7LPaARsuoIQEsP3W2KKCNUSBwygy1vnHtfj02:HoLP5RsuoFEi3W2KK0UdKn77
Yara None matched
VirusTotal Search for analysis
Name ab8c0780873291e6_sqlite3.dll
Submit file
Filepath c:\program files (x86)\pc cleaner\sqlite3.dll
Size 852.7KB
Processes 2156 (PC_Cleaner.tmp)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 14e1f7ebce8eed6a8d1f49bca82115ae
SHA1 76eb44368bb516c6a958ecad2f6a44295c69e2bb
SHA256 ab8c0780873291e65723db4acd0eb58476781a842087efee8770f825906d1332
CRC32 9340733A
ssdeep 24576:dTtmtnhKqK75YJ4+X8NLXBIXcgVMU//GlM:dshc84y8NLXBUj/
Yara
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
VirusTotal Search for analysis
Name d83ca335f685c018_net.db
Submit file
Filepath c:\program files (x86)\pc cleaner\net.db
Size 1.9MB
Processes 2156 (PC_Cleaner.tmp)
Type SQLite 3.x database, last written using SQLite version 3009002
MD5 6e6a4d04a20bf3f46f3feb94d9d6fa23
SHA1 ccbeb8dcabdeb7d05687405325a008a50f573554
SHA256 d83ca335f685c018c8edba6760ace360f3d26362fb067f548bd1bd924c204af6
CRC32 E70BEE75
ssdeep 49152:sKaOirx5nZSp0LzifuUPLdDw59bnCqDgEShLMCgktSVvIQ/w+8/FsIYcyjyoo98s:/3HWs
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 5b0728186e5426e5_pc cleaner.lnk
Submit file
Filepath C:\Users\test22\Desktop\PC Cleaner.lnk
Size 1.0KB
Processes 2156 (PC_Cleaner.tmp)
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Wed Dec 13 14:00:31 2023, mtime=Wed Dec 13 14:00:31 2023, atime=Fri Mar 5 02:06:12 2021, length=9000864, window=hide
MD5 5fd6e5b2e2b51b2683c99ee70e2e8cff
SHA1 e615727a486461bbd6c4023e73c9b11e5413322d
SHA256 5b0728186e5426e50825a7f3819422c4b098b2345538467b3875184be0c9eb5b
CRC32 86C67C03
ssdeep 24:8mdVdOEkYSmScBxA6k/NYdnmJWdnmlUPPyN:8mdVdOvMQ6JdnwWdnTnyN
Yara
  • lnk_file_format - Microsoft Windows Shortcut File Format
  • Antivirus - Contains references to security software
  • Lnk_Format_Zero - LNK Format
VirusTotal Search for analysis
Name 014a19179c29ae8c_danish.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\danish.ini
Size 75.1KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 046a4e40bc124874f9eef89b85b28518
SHA1 aadd6ab371c6a51a28cf6673776e15fd526699bb
SHA256 014a19179c29ae8c2902b96128db0aa2d70fbd27793f58e3499dbc61137b840d
CRC32 D8D16B8E
ssdeep 1536:m9dU9dHhzKQkfSyhiBQRFxU3wuvSF+dGamUUGd:j3pKQ3QRFx0q+dt1UC
Yara None matched
VirusTotal Search for analysis
Name 98b2d5e74a080a1b_dutch.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\dutch.ini
Size 78.6KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 5579cabbe62f8604baeed0f01b1cf516
SHA1 d6e4a9d55bb501daa325fae610cefb2ac5c9156f
SHA256 98b2d5e74a080a1ba9e24a5e249fc9014a6deff36ae67fb7e5649dce9dd9b42d
CRC32 91F60D27
ssdeep 1536:oQfI2n7N1+A8IQtdlMgubq963vein3XZ6nSUC7kWUHc3x90BHnWKkYZAb/9f:oGI276RIQtdlMtqqvein3XZ6nSUC7ktY
Yara None matched
VirusTotal Search for analysis
Name e3038c1f9f88b80f_ulist.txt
Submit file
Filepath c:\program files (x86)\pc cleaner\ulist.txt
Size 18.4KB
Processes 2156 (PC_Cleaner.tmp)
Type ASCII text, with CRLF line terminators
MD5 0a98387bc136d528f220300db04a8f3c
SHA1 5fad82017a8c1c872a29b1899ee2a69fe46b775e
SHA256 e3038c1f9f88b80fcd4e34a8999caa2073d010c2408391b5c8ce00f758be0206
CRC32 2A0935A8
ssdeep 384:pr4hmymynKIZ+uCqeAycVmdads40C2w8GpWON5Sy4:primymYpkqefcVGads4J2w86N5Sy4
Yara None matched
VirusTotal Search for analysis
Name 388a796580234efc__setup64.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-H3TE1.tmp\_isetup\_setup64.tmp
Size 6.0KB
Processes 2156 (PC_Cleaner.tmp)
Type PE32+ executable (console) x86-64, for MS Windows
MD5 e4211d6d009757c078a9fac7ff4f03d4
SHA1 019cd56ba687d39d12d4b13991c9a42ea6ba03da
SHA256 388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
CRC32 2CDCC338
ssdeep 96:sfkcXegaJ/ZAYNzcld1xaX12p+gt1sONA0:sfJEVYlvxaX12C6A0
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name a84946f4fb162454_russian.ini
Submit file
Filepath c:\program files (x86)\pc cleaner\russian.ini
Size 116.0KB
Processes 2156 (PC_Cleaner.tmp)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 b6ad0a22fc05bc5679555e81ad974bb4
SHA1 22debc8206363d8cef59acabf9307f8540c16417
SHA256 a84946f4fb162454e22d208b12f7caed9c2bc5b8fbd488faab9b90dbad8b938f
CRC32 0C967AD0
ssdeep 3072:5wV6YUVc5gbZvfb0P2I6HDpj3bQ1/ghLzk9ji6kUvFNTrVAeftE3xQ7bsespwtgq:5WUVc5gbZvf4P6HDpj301/yLzk9ji6kw
Yara None matched
VirusTotal Search for analysis
Name be00aa44894fafdd_PCCleaner.bmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-H3TE1.tmp\PCCleaner.bmp
Size 74.9KB
Processes 2156 (PC_Cleaner.tmp)
Type PC bitmap, Windows 3.x format, 455 x 56 x 24
MD5 ad9069fe722fb813ea15b8f4d933d248
SHA1 9d75d39b2e2083fd31650d2a55403ae9807791be
SHA256 be00aa44894fafdd7b3097770fbe521e85cfce92a0b39626083bbe7c6e22ebbd
CRC32 D0530B34
ssdeep 192:phfAGpUbs/Q8NgEuDprt2blv/VAw2RTao/jpGZDvUib:pmGpU2Q8NgEG9t2Zv9eRt/NFu
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis